TechSpot

Hijack This logfile (first post to this board)

By 3DTD
Oct 17, 2006
  1. Five days ago I started working on a friend's computer. Knew I was in trouble when I saw the green dots floating across the screen just after POST (no SP2 upgrade).

    He had no anti-virus program, no firewall, no nothin'.

    Installed AVG anti virus, ran it, found 11 viruses, trojan horses, hijackers--you name it--and killed them. Installed Spybot, AdAware, and CWShredder, which identified about 400 instances of spyware. But none could kill 'em. Each would SAY it had fixed what it had found, but upon running the same program immediately afterwards, there they (still) were. Hmmm....

    Read in the November issue of CPU (Computer Power User) magazine about a program called Zappit System Cleaner. Downloaded, installed it, ran it--it did the job, and let Spybot and Adaware do theirs.

    Got all (about 65) Windows updates. All of 'em installed except one. Haven't figured that one out yet. Has to do with "16-bit MS-DOS Subsystem", and the Microsoft information on Q324767 will probably be of some help once I can get to it.

    So it's running much better, but still isn't right. I've attached the HijackThis logfile, and am hoping that someone will be able to tell me if there's still a problem with this thing.

    Hey, just because I read CPU doesn't mean I AM one (a Power User).
     
  2. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Hello and welcome to Techspot.

    That system is still full of nasties.

    You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

    Turn off system restore.(XP/ME only) See how here.> http://www.bleepingcomputer.com/forums/tutorial56.html

    Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how here.> http://www.bleepingcomputer.com/forums/tutorial61.html

    In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how here.> http://www.bleepingcomputer.com/forums/tutorial62.html

    Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

    Click on the processes tab and end process for(if there).

    explorer32.exe

    Bus.exe
    Rjk.exe
    Tcf.exe

    Tuh.exe
    Pnr.exe
    Hhi.exe

    Lsp.exe
    Fum.exe
    Teh.exe

    Obs.exe
    Bsp.exe
    Agf.exe

    Kmg.exe
    Onb.exe
    Trd.exe

    Gaf.exe
    Cml.exe
    Sdu.exe

    Vhr.exe
    Jum.exe
    Mfd.exe

    Aat.exe
    Kid.exe
    Kav.exe

    Klg.exe
    Ssr.exe
    Rds.exe

    Gft.exe

    Close task manager.

    Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.top-search.us/index.html

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.top-search.us/search.html

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.top-search.us/index.html

    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.top-search.us/search.html

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.top-search.us/search.html

    R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.top-search.us/search.html

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.top-search.us/index.html

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;

    O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)

    O4 - HKLM\..\Run: [Win32 Time Zone] C:\WINDOWS\System32\explorer32.exe

    O4 - HKCU\..\Run: [Obi] C:\WINDOWS\System32\Bus.exe

    O4 - HKCU\..\Run: [Win32SystemMonitor] C:\WINDOWS\Rjk.exe

    O4 - HKCU\..\Run: [Jkb] C:\WINDOWS\Tcf.exe

    O4 - HKCU\..\Run: [Ipb] C:\WINDOWS\System32\Tuh.exe

    O4 - HKCU\..\Run: [Kdg] C:\WINDOWS\Pnr.exe

    O4 - HKCU\..\Run: [Fce] C:\WINDOWS\Hhi.exe

    O4 - HKCU\..\Run: [Eov] C:\WINDOWS\System32\Lsp.exe

    O4 - HKCU\..\Run: [Sge] C:\WINDOWS\System32\Fum.exe

    O4 - HKCU\..\Run: [Qmg] C:\WINDOWS\System32\Teh.exe

    O4 - HKCU\..\Run: [Gmr] C:\WINDOWS\Obs.exe

    O4 - HKCU\..\Run: [Ofg] C:\WINDOWS\System32\Bsp.exe

    O4 - HKCU\..\Run: [Boi] C:\WINDOWS\Agf.exe

    O4 - HKCU\..\Run: [Lmj] C:\WINDOWS\System32\Kmg.exe

    O4 - HKCU\..\Run: [Loj] C:\WINDOWS\System32\Onb.exe

    O4 - HKCU\..\Run: [Csn] C:\WINDOWS\System32\Trd.exe

    O4 - HKCU\..\Run: [Kqq] C:\WINDOWS\Gaf.exe

    O4 - HKCU\..\Run: [Mnv] C:\WINDOWS\Cml.exe

    O4 - HKCU\..\Run: [Ujd] C:\WINDOWS\System32\Sdu.exe

    O4 - HKCU\..\Run: [Beg] C:\WINDOWS\Vhr.exe

    O4 - HKCU\..\Run: [Grd] C:\WINDOWS\System32\Jum.exe

    O4 - HKCU\..\Run: [Sso] C:\WINDOWS\Mfd.exe

    O4 - HKCU\..\Run: [Lgn] C:\WINDOWS\System32\Aat.exe

    O4 - HKCU\..\Run: [Vve] C:\WINDOWS\Kid.exe

    O4 - HKCU\..\Run: [Gpc] C:\WINDOWS\System32\Kav.exe

    O4 - HKCU\..\Run: [Rdd] C:\WINDOWS\System32\Klg.exe

    O4 - HKCU\..\Run: [Cqp] C:\WINDOWS\Ssr.exe

    O4 - HKCU\..\Run: [Jfu] C:\WINDOWS\System32\Rds.exe

    O4 - HKCU\..\Run: [Tda] C:\WINDOWS\System32\Gft.exe

    O4 - HKCU\..\Run: [Win32 Time Zone] C:\WINDOWS\System32\explorer32.exe

    Click on the fix checked button.

    Close HJT.

    Locate and delete the following bold files and/or directories(if there).

    C:\WINDOWS\System32\Bus.exe
    C:\WINDOWS\Rjk.exe
    C:\WINDOWS\Tcf.exe

    C:\WINDOWS\System32\Tuh.exe
    C:\WINDOWS\Pnr.exe
    C:\WINDOWS\Hhi.exe

    C:\WINDOWS\System32\Lsp.exe
    C:\WINDOWS\System32\Fum.exe
    C:\WINDOWS\System32\Teh.exe

    C:\WINDOWS\Obs.exe
    C:\WINDOWS\System32\Bsp.exe
    C:\WINDOWS\Agf.exe

    C:\WINDOWS\System32\Kmg.exe
    C:\WINDOWS\System32\Onb.exe
    C:\WINDOWS\System32\Trd.exe

    C:\WINDOWS\Gaf.exe
    C:\WINDOWS\Cml.exe
    C:\WINDOWS\System32\Sdu.exe

    C:\WINDOWS\Vhr.exe
    C:\WINDOWS\System32\Jum.exe
    C:\WINDOWS\Mfd.exe

    C:\WINDOWS\System32\Aat.exe
    C:\WINDOWS\Kid.exe
    C:\WINDOWS\System32\Kav.exe

    C:\WINDOWS\System32\Klg.exe
    C:\WINDOWS\Ssr.exe
    C:\WINDOWS\System32\Rds.exe

    C:\WINDOWS\System32\Gft.exe
    C:\WINDOWS\System32\explorer32.exe

    Reboot into normal mode, turn system restore back on and rehide your protected OS files.

    Post a fresh HJT log.


    Regards Howard :wave: :wave:

    This thread is for the use of 3DTD only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  3. 3DTD

    3DTD TS Rookie Topic Starter

    Thanks, Howard

    Really appreciate your taking the time to post such a detailed reply.

    I'd already turned off the System Restore, but that's as far as I'd gone. I'll try following your instructions to the letter when I get back home (goofing off at work now) tonight, and will let you know the results.

    Mark
     
  4. 3DTD

    3DTD TS Rookie Topic Starter

    new HJT logfile

    Howard,

    I followed your intructions--please see attached logfile.

    Running much better, thanks again.

    See anything else amiss?

    Regards,
    Mark
     
  5. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Your HJT log is now clean.

    If you have any further virus/spyware problems, please post in this thread.

    Regards Howard :)

    This thread is for the use of 3DTD only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...